StackRadar

CVE-2026-56408

Medium

Advisory

Published 21 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,393
of 17,790 indexed, latest versions
Container images
1,377
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,393 of 17,790 indexed charts deploy, on 1,377 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+32 more2.5.0-1+deb12u3, 2.8.2-1~deb13u11,124
expatapk2.5.0-r4, 2.6.4-r0, 2.6.4-r1, 2.7.0-r0+9 more2.8.2-r0253
OSV records
ALPINE-CVE-2026-56408CGA-hpc5-6g7r-r4rpDEBIAN-CVE-2026-56408UBUNTU-CVE-2026-56408
Also known as
CGA-p8q2-2q8j-3g4f, CGA-pf9w-48v9-4g6r, CGA-qh6j-h9pj-wj7h

Charts affected

1,393 by stars
ChartLatestAffected imagesRadar Score
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,985
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
expat@2.5.0-1
2.5.0-1+deb12u3
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
expat@2.5.0-1
2.5.0-1+deb12u3
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

45,656
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

14,013
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
expat@2.4.7-1ubuntu0.2
no fix listed
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

32,638
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

9,429
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,657
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

6,321
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
kuzwolka/aws9:news3e8880fbbb96
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
kuzwolka/aws9:blog4a7707410bf1
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
kuzwolka/aws9:shop84a9d9766345
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

18,436
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
expat@2.4.7-1ubuntu0.5
no fix listed

Open the chart page →

3,310
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

6,321
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
expat@2.2.9-1ubuntu0.4
no fix listed
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
expat@2.2.9-1ubuntu0.4
no fix listed
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

20,794
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

7,246
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

5,117
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

8,029
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

22,929
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

10,225
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

13,517
colosseumbook-k8sinfra-v21.0.183 of 5See more

colosseum book-k8sinfra-v2 1.0.18

3 of the 5 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
expat@2.4.7-1ubuntu0.7
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
sysnet4admin/colosseum-prm:log5802bfcd7fed
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

27,215
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

6,289
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed
library/cassandra:3.11.65aa8400b4b3b
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

19,311
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

8,339
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

27,554
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

14,513
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
expat@2.2.9-1build1
no fix listed

Open the chart page →

11,958
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
expat@2.7.1-r0
2.8.2-r0

Open the chart page →

2,399
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

10,661
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

8,024
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
expat@2.2.9-1build1
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
expat@2.2.9-1build1
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
expat@2.2.9-1build1
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
expat@2.2.9-1build1
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
expat@2.2.9-1build1
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
expat@2.2.9-1build1
no fix listed

Open the chart page →

88,618
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

3,334
lamphttpdcamptocamp31.0.111 of 1See more

lamphttpd camptocamp3 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
library/httpd:2.4-alpine1b766f17b840
expat@2.8.1-r0
2.8.2-r0

Open the chart page →

902
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

5,062
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
puppet/puppet-agent:7.14.00b6fd9a6b7da
expat@2.2.5-3ubuntu0.7
no fix listed

Open the chart page →

6,153
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
expat@2.4.7-1ubuntu0.5
no fix listed

Open the chart page →

5,935
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

10,867
apachecamptocamp-apache0.4.01 of 2See more

apache camptocamp-apache 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
camptocamp/mapserver:latestbf2e8e118c9b
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,490
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

14,179
pagescarina-pages1.0.02 of 3See more

pages carina-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
pagescarmel-pages-dell1.0.02 of 3See more

pages carmel-pages-dell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,242
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
expat@2.2.9-1build1
no fix listed

Open the chart page →

9,525
catalyst-agentscatalyst-agents0.1.312 of 18See more

catalyst-agents catalyst-agents 0.1.31

2 of the 18 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
expat@2.6.4-r0
2.8.2-r0
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

17,099
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

15,490
charon-relaycharonOfficialVerified publisher0.8.01 of 2See more

charon-relay charon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

4,440
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

7,501
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

5,840
kitchenowlchart-kitchenowl0.1.122 of 2See more

kitchenowl chart-kitchenowl 0.1.12

2 of the 2 container images this version deploys carry CVE-2026-56408.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
expat@2.7.1-2
2.8.2-1~deb13u1
tombursch/kitchenowl-web:v0.7.8517f808eee66
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

4,829

Container images carrying it

1,377 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
expat@2.4.7-1ubuntu0.4
no fix listed
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
expat@2.7.4-r0
2.8.2-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
expat@2.4.7-1ubuntu0.3
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
expat@2.4.7-1ubuntu0.3
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
expat@2.4.7-1ubuntu0.5
no fix listed
1
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
expat@2.7.5-r0
2.8.2-r0
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/zazukoians/qlever-server:v0.10.11de7869ab46e
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
expat@2.7.1-r0
2.8.2-r0
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
expat@2.2.5-3ubuntu0.9
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
expat@2.2.9-1ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
expat@2.4.7-1ubuntu0.7
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
expat@2.2.5-3ubuntu0.9
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
expat@2.6.1-2ubuntu0.3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
expat@2.7.5-r0
2.8.2-r0
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
expat@2.7.5-r0
2.8.2-r0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
expat@2.5.0-1
2.5.0-1+deb12u3
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
expat@2.7.4-1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
no fix listed
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
expat@2.7.5-r0
2.8.2-r0
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
expat@2.7.3-r0
2.8.2-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.